Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 610600 (CVE-2017-6074) - kernel: use after free in DCCP protocol (CVE-2017-6074)
Summary: kernel: use after free in DCCP protocol (CVE-2017-6074)
Alias: CVE-2017-6074
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal critical (vote)
Assignee: Gentoo Kernel Security
Depends on: 611824
  Show dependency tree
Reported: 2017-02-22 20:08 UTC by Thomas Deutschmann (RETIRED)
Modified: 2022-03-25 22:58 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2017-02-22 20:08:43 UTC
A flaw was found in the linux kernels implementation of DCCP protocol in which a local user could create influence timing in which a skbuff could be used after it had been freed by the kernel.  An attacker is able to craft structures allocated in this free memory will be able to create memory corruption, privilege escalation or crash the system. An attacker must have a local account access on the system, this is not a remote attack. An attack requires IPV6 support to be enabled in the system.

Upstream patch:
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-02-24 12:02:40 UTC
There's no upstream release containing the fix yet.

Fix present in

Comment 2 Alice Ferrazzi Gentoo Infrastructure gentoo-dev 2017-02-25 03:59:01 UTC
also in 
Comment 3 Justin Lecher (RETIRED) gentoo-dev 2017-02-25 10:53:15 UTC
commit 84dd15749e0931a21fcced926b60f054a5ae155a
Author: Justin Lecher <>
Date:   Sat Feb 25 10:45:17 2017 +0000

    sys-kernel/aufs-sources: Bump to latest aufs, genpatches and linux release fixes CVE-2017-6074

    drop old


    Package-Manager: Portage-2.3.3, Repoman-2.3.1
    Signed-off-by: Justin Lecher <>
Comment 5 kuzetsa CatSwarm (kuza for short) 2017-02-26 15:32:33 UTC
Currently, only other upstream branch with a fix looks like 4.4.y

$ git tag --contains a95df078e86624ee330e82aad34cfd3b5fcf21ce

Fix for other longterm branches (upstream) don't appear to be in-tree yet.

Upstream 4.10.y branch (any/all post-RC versions) contains the original version which is backported by genpatches-4.9-14

$ git tag --contains 5edabca9d4cff7f1f2b68f0bac55ef99d9798ba4

sys-kernel/ck-sources: CVE-2017-6074 (fixed by genpatches 4.9-14 / linux 4.10)
Comment 6 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-25 22:58:30 UTC
Fixed in 4.10, 4.9.13